S0170RS6-T20-S0170-Z · Full risk code

Highly Customized Phishing Attack

高度客製化釣魚攻擊

Operation & Monitoring
Risk Description

When an employee receives an email imitating a supervisor's writing style and referencing an actual recent project; due to unmitigated control gaps, the content is natural and the context plausible, triggering external stakeholder impacts and causing the employee follows the instructions before realizing it is fraudulent, and existing phishing awareness training proves entirely ineffective.

Framework Mappings

NIST AI 600-1Information Security
MITRE ATLASAML.T0052
EU AI ActArt.50
NIST AI RMFMANAGE 2.4
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 4

Risk Treatment & Implementation Guidance

Deploy advanced email security detecting highly tailored phishing that mimics writing style and plausible context; Require out-of-band verification for financial and sensitive instructions beyond email content; Train staff on social-engineering awareness covering AI-enhanced personalized attacks